CVE-2026-6025 | Totolink A7100RU 7.4cu.2313_b20191024 CGI /cgi-bin/cstecgi.cgi setSyslogCfg enable os command injection (EUVD-2026-21314)
A vulnerability was found in Totolink A7100RU 7.4cu.2313_b20191024. It has been declared as critical. This affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument enable leads to os command injection.
This vulnerability is referenced as CVE-2026-6025. It is possible to launch the attack remotely. Furthermore, an exploit is available.